Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator is configuring Microsoft Defender for Cloud Apps. The administrator needs to discover which cloud apps are being used in the organization and then block usage of unsanctioned apps in real time using a reverse proxy. Which two Defender for Cloud Apps features must be configured? (Select the two correct options.)

⚠ Common exam trap

It's easy for candidates to confuse App governance (which manages OAuth app permissions) with the reverse proxy functionality of Conditional Access App Control, or assume Cloud Discovery alone is sufficient for blocking, when it only provides visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cloud Discovery

Cloud Discovery is the correct feature because it identifies which cloud apps are in use by analyzing traffic logs from the organization's network. This provides the visibility needed to determine which apps are unsanctioned. Conditional Access App Control is the correct feature because it uses a reverse proxy to enforce real-time access controls, blocking unsanctioned apps at the session level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Discovery

    Why this is correct

    Cloud Discovery is the feature in Microsoft Defender for Cloud Apps that ingests and analyzes traffic logs from network proxies and firewalls to identify all cloud apps in use, including unsanctioned shadow IT. It assigns risk scores to each discovered app and allows you to sanction or unsanction them based on organizational policy. This analysis is the foundational step for any subsequent control, such as Conditional Access App Control.

  • App governance

    Why it's wrong here

    App governance is a specialized capability in Microsoft Defender for Cloud Apps that focuses on monitoring and governing OAuth-enabled applications that have been granted permissions to Microsoft 365 data. You can create policies to detect anomalous behavior and require app permissions to be reviewed, but it does not analyze network logs to discover unknown apps. Because it operates after an app has already been installed and granted consent, it cannot serve as the initial discovery mechanism.

  • Conditional Access App Control

    Why this is correct

    Conditional Access App Control (CAAC) is a reverse proxy integration that routes a user's session through Defender for Cloud Apps when a Conditional Access policy triggers. It enables real-time enforcement of session policies, such as blocking downloads or preventing access to unsanctioned apps, but it requires prior knowledge of which apps are in use—typically from Cloud Discovery. This makes CAAC an effective remediation and control layer, not the discovery method.

  • OAuth app permissions

    Why it's wrong here

    OAuth app permissions are the delegated or application permissions granted to third-party apps via Microsoft Entra ID, allowing them to access resources like Exchange Online or SharePoint. Administrators can review, approve, or revoke these permissions using reports and compliance features, but this does not uncover apps that were not granted OAuth permissions or that are accessed via other means. It is a post-hoc governance layer rather than a tool for identifying or blocking unsanctioned cloud applications.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.